ZeroHour

CVE-2026-57825

CVSS 3.1
5.7 medium
EPSS
<1%p24
Published
()
Modified
Description

In the opam package before 2.5.2 for OCaml, the sandbox protection mechanism can be bypassed because symlinks are mishandled during use of .install files.

Weakness
CWE-61
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.